ELSA-2026-1574

ELSA-2026-1574 - gimp:2.8 security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-01-29

Description


gimp
[2:2.8.22-26.4]
- fix CVE-2025-14422

[2:2.8.22-26.3]
- fix CVE-2025-10920
- fix CVE-2025-10921
- fix CVE-2025-10922
- fix CVE-2025-10923
- fix CVE-2025-10924
- fix CVE-2025-10925
- fix CVE-2025-10934

[2:2.8.22-26.2]
- fix CVE-2025-5473 (RHEL-95696)

[2:2.8.22-26.1]
- fix CVE-2025-48797 (RHEL-93503)
- fix CVE-2025-48798 (RHEL-93506)

[2:2.28.22-26]
- bump spec

[2:2.8.22-25]
- fix CVE-2023-44442
- fix CVE-2023-44444
- disable gimp-2.8.22-python-path.patch required for flatpak
- partially cherry-pick from upstream commit 2987f012 to fix fclose leak
Resolves: RHEL-17048 RHEL-17060

[2:2.8.22-24]
- fallback to RPM gegl

[2:2.8.22-23]
- enforce gegl04

[2:2.8.22-22]
- change gegl requirement to gegl04

[2:2.8.22-21]
- set manual shebang in python files

pygobject2
[2.28.7-5]
- bump spec to fix NVR

[2.28.7-4]
- update python macro to python2

[2.28.7-3]
- Add MIT license

[2.28.7-2.1]
- Fix python shebangs (#1580854)

[2.28.7-2]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild

[2.28.7-1]
- Update to 2.28.7

[2.28.6-19]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild

[2.28.6-18]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild

[2.28.6-17]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild

[2.28.6-16]
- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages

pygtk2
[2.24.0-25]
- Fix shebang mangling for _prefix=app (#1907579)
- disable numpy for flatpak (#1907579)

[2.24.0-24]
- remove libglade dependency and sub-package (#1622134)

[2.24.0-23.1]
- fix python2 regex in sed command

[2.24.0-23]
- resotre doc sub package

[2.24.0-22]
- fix python2 macros

[2.24.0-21.1]
- Fix python shebangs (#1580855)

[2.24.0-21]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild

[2.24.0-20]
- Try again to fix shebangs

[2.24.0-19]
- Fix shebangs

[2.24.0-18]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild

python2-pycairo
[1.16.3-7]
- bump spec for NVR fix

[1.16.3-6]
- Rename pycairo to python2-pycairo (RCM-39388)

[1.16.3-5]
- Add python3 packages (RCM-39388)
- remove python3-test due its missing in build root

[1.16.3-4]
- Setup python2 stream branch for python2 binding of cairo library

[1.16.3-3]
- Remove the python2 subpackages
https://bugzilla.redhat.com/show_bug.cgi?id=1590820

[1.16.3-2]
- Allow Python 2 for build
See: https://hurl.corp.redhat.com/rhel8-py2

- Skip tests on Python 2 (python2-pytest is being removed)

[1.16.3-1]
- Update to 1.16.3

[1.16.1-1]
- Update to 1.16.1

[1.16.0-1]
- Update to 1.16.0

[1.15.6-1]
- Update to 1.15.6


Related CVEs


CVE-2025-14422

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) gimp-2.8.22-26.module+el8.10.0+90778+ba4a24eb.4.src.rpmf5ad00392ae77900f9e2cd5ff69d19e209bf8983df734296a7a22e2c3717581b-ol8_aarch64_appstream
pygobject2-2.28.7-5.module+el8.10.0+90497+ae78887f.src.rpmf2b6af9a436a0ac325d7ed2dc45c5c7d2b479753d5bcc456fc952e48cd198892-ol8_aarch64_appstream
pygtk2-2.24.0-25.module+el8.9.0+90151+46a7e4b5.src.rpmf039bb4150fe124bdb1b2ad25a51fbccdb61b56e76e2eceb04626322eb3bf1b0-ol8_aarch64_appstream
python2-pycairo-1.16.3-7.module+el8.10.0+90497+ae78887f.src.rpm546c0b737a1ad1280ea1fa8b46867e48a644d1b38f71b1f44c0597141d220365-ol8_aarch64_appstream
gimp-2.8.22-26.module+el8.10.0+90778+ba4a24eb.4.aarch64.rpmf1638af52cee7a29b3c084e7ae86e41fc74b6d8d0cf625d422809928a6da9aaf-ol8_aarch64_appstream
gimp-devel-2.8.22-26.module+el8.10.0+90778+ba4a24eb.4.aarch64.rpm6c63e221d60d252dfe914c34ed391b6077a20649cc2ac0ac225c7923ee4bcf55-ol8_aarch64_appstream
gimp-devel-tools-2.8.22-26.module+el8.10.0+90778+ba4a24eb.4.aarch64.rpm2a850ed78c9191921aa5b6ace1592d5db74f65f17ac6154bebbecc2a3ef1c5c0-ol8_aarch64_appstream
gimp-libs-2.8.22-26.module+el8.10.0+90778+ba4a24eb.4.aarch64.rpmf44c5994cf55abff6696b7b32c7022db2e6ccba8872cba6671664f7d41916617-ol8_aarch64_appstream
pygobject2-2.28.7-5.module+el8.10.0+90497+ae78887f.aarch64.rpm697745da92fdda68afc4a28ebab9bb0108a616c18f5179f318a6aa1872a6e866-ol8_aarch64_appstream
pygobject2-codegen-2.28.7-5.module+el8.10.0+90497+ae78887f.aarch64.rpm7ba269d3b647be8cf33097fc7a82228e5073485dc794524f756849b961ca1cf6-ol8_aarch64_appstream
pygobject2-devel-2.28.7-5.module+el8.10.0+90497+ae78887f.aarch64.rpm2da7da07bc9349133b9c3ffb0e74131db72024531aa526b8a3e8cec89b62ca75-ol8_aarch64_appstream
pygobject2-doc-2.28.7-5.module+el8.10.0+90497+ae78887f.aarch64.rpm2f593b1f9ec7099e8c71b89d0e680fdf6aaa38675d8ae8843ed372df40906ca6-ol8_aarch64_appstream
pygtk2-2.24.0-25.module+el8.9.0+90151+46a7e4b5.aarch64.rpmebcba5b9fd0a569644e692d18ee447b11aefdc546dcee720c2ea3cbdc4f4b890-ol8_aarch64_appstream
pygtk2-codegen-2.24.0-25.module+el8.9.0+90151+46a7e4b5.aarch64.rpm6804209be9d482549468d30e62e8fec965696076554db653e28f07504e107fbd-ol8_aarch64_appstream
pygtk2-devel-2.24.0-25.module+el8.9.0+90151+46a7e4b5.aarch64.rpm63f1c4141df33d4f13da5c4b6737af826b7f837ac3c52da55e7522ba1cbdc31f-ol8_aarch64_appstream
pygtk2-doc-2.24.0-25.module+el8.9.0+90151+46a7e4b5.noarch.rpm08de36761520a45a1ff60fbd54e511ebc7e03e1abfa95c8938c1b3cda33009e0-ol8_aarch64_appstream
python2-cairo-1.16.3-7.module+el8.10.0+90497+ae78887f.aarch64.rpmb3525b5ea4f9c6c2d1fe567bed6099962fb2dfd29bede936970a073d3c07072d-ol8_aarch64_appstream
python2-cairo-devel-1.16.3-7.module+el8.10.0+90497+ae78887f.aarch64.rpmf5184a0c70a5101af09574f608dc5d57525d954a4c7e0068dfb0eee4cb6a28b7-ol8_aarch64_appstream
Oracle Linux 8 (x86_64) gimp-2.8.22-26.module+el8.10.0+90778+ba4a24eb.4.src.rpmf5ad00392ae77900f9e2cd5ff69d19e209bf8983df734296a7a22e2c3717581b-ol8_x86_64_appstream
pygobject2-2.28.7-5.module+el8.10.0+90497+ae78887f.src.rpmf2b6af9a436a0ac325d7ed2dc45c5c7d2b479753d5bcc456fc952e48cd198892-ol8_x86_64_appstream
pygtk2-2.24.0-25.module+el8.9.0+90151+46a7e4b5.src.rpmf039bb4150fe124bdb1b2ad25a51fbccdb61b56e76e2eceb04626322eb3bf1b0-ol8_x86_64_appstream
python2-pycairo-1.16.3-7.module+el8.10.0+90497+ae78887f.src.rpm546c0b737a1ad1280ea1fa8b46867e48a644d1b38f71b1f44c0597141d220365-ol8_x86_64_appstream
gimp-2.8.22-26.module+el8.10.0+90778+ba4a24eb.4.x86_64.rpmdedfd68b8a858e8c4a5ef1c939b1380b90591492e1f210f601f1c5bd46c5903b-ol8_x86_64_appstream
gimp-devel-2.8.22-26.module+el8.10.0+90778+ba4a24eb.4.x86_64.rpmd4f51b951be4e83accc8723cc57c98ec2865ed48de5e77a43723f462eb938bce-ol8_x86_64_appstream
gimp-devel-tools-2.8.22-26.module+el8.10.0+90778+ba4a24eb.4.x86_64.rpmec4d776a0cc43f75e2665dea65f41f943ec4d30b3b2e9e00e1e9edbecc8a8b66-ol8_x86_64_appstream
gimp-libs-2.8.22-26.module+el8.10.0+90778+ba4a24eb.4.x86_64.rpm624888012b95f3b0a7775efb536496da464b89088ff2986ae949c2f927f39df4-ol8_x86_64_appstream
pygobject2-2.28.7-5.module+el8.10.0+90497+ae78887f.x86_64.rpm57ae4e3ea05328596812a517c996ea4c9adda0c7f2e28bcb4d25ca6c0020a5ad-ol8_x86_64_appstream
pygobject2-codegen-2.28.7-5.module+el8.10.0+90497+ae78887f.x86_64.rpm8d5aa2c450cd2cb6037dfd721fd424e6a64f83b3b0febd08941dd447aa4536fc-ol8_x86_64_appstream
pygobject2-devel-2.28.7-5.module+el8.10.0+90497+ae78887f.x86_64.rpm3876c60435a4a075833ef14beea16bb74dae21a98c36e9e8174969c6ceb62aba-ol8_x86_64_appstream
pygobject2-doc-2.28.7-5.module+el8.10.0+90497+ae78887f.x86_64.rpm32032c9385ad1f1d6551945f5d722197f6eaf56050a9fb452b675ca5ef6570eb-ol8_x86_64_appstream
pygtk2-2.24.0-25.module+el8.9.0+90151+46a7e4b5.x86_64.rpm3231b036ebfb1ddcfee4cc0a0dfb016c3d08200decd7bf96fe65c2d3853a9c55-ol8_x86_64_appstream
pygtk2-codegen-2.24.0-25.module+el8.9.0+90151+46a7e4b5.x86_64.rpmf54b672a43d5be06fbe020c956a9041a7d9cb7ccda3d55ee88aefdaeef4a0d47-ol8_x86_64_appstream
pygtk2-devel-2.24.0-25.module+el8.9.0+90151+46a7e4b5.x86_64.rpmce2349c3fc91801f567947f237a419c664226e9230a0ba204cb15d57c0b4f711-ol8_x86_64_appstream
pygtk2-doc-2.24.0-25.module+el8.9.0+90151+46a7e4b5.noarch.rpm08de36761520a45a1ff60fbd54e511ebc7e03e1abfa95c8938c1b3cda33009e0-ol8_x86_64_appstream
python2-cairo-1.16.3-7.module+el8.10.0+90497+ae78887f.x86_64.rpmaffb725f331e18fc5cae82b37832af8e4d99ddb1d4db6fa6aebc9e966bb84da5-ol8_x86_64_appstream
python2-cairo-devel-1.16.3-7.module+el8.10.0+90497+ae78887f.x86_64.rpm7b80515f9bbff35c9e70bb6d7b53409aacbdcf8b830641a1cb6d6acb96e3b755-ol8_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete